A CISO asks the network team to design a network that assumes breach. Which architecture element is most aligned with this philosophy?
Select an answer to reveal the explanation.
Short Explanation
Here's the deal — b is correct because assume-breach architecture focuses on limiting lateral movement once an attacker is inside; internal segmentation firewalls directly address this. A is wrong because larger perimeter firewalls only address north-south traffic and do not limit internal lateral movement.
Full Explanation
B is correct because assume-breach architecture focuses on limiting lateral movement once an attacker is inside; internal segmentation firewalls directly address this. A is wrong because larger perimeter firewalls only address north-south traffic and do not limit internal lateral movement. C is wrong because updating IDS signatures helps detection but does not limit what an attacker can do after breach. D is wrong because a second DMZ addresses perimeter redundancy, not internal breach containment.